Логотип exploitDog
bind: "CVE-2024-32465"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2024-32465"

Количество 15

Количество 15

ubuntu логотип

CVE-2024-32465

около 1 года назад

Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but vulnerabilities allow those protections to be bypassed. In the context of cloning local repositories owned by other users, this vulnerability has been covered in CVE-2024-32004. But there are circumstances where the fixes for CVE-2024-32004 are not enough: For example, when obtaining a `.zip` file containing a full copy of a Git repository, it should not be trusted by default to be safe, as e.g. hooks could be configured to run within the context of that repository. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid using Git in repositories that have been obtained via archives from untrusted sources.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2024-32465

около 1 года назад

Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but vulnerabilities allow those protections to be bypassed. In the context of cloning local repositories owned by other users, this vulnerability has been covered in CVE-2024-32004. But there are circumstances where the fixes for CVE-2024-32004 are not enough: For example, when obtaining a `.zip` file containing a full copy of a Git repository, it should not be trusted by default to be safe, as e.g. hooks could be configured to run within the context of that repository. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid using Git in repositories that have been obtained via archives from untrusted sources.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2024-32465

около 1 года назад

Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but vulnerabilities allow those protections to be bypassed. In the context of cloning local repositories owned by other users, this vulnerability has been covered in CVE-2024-32004. But there are circumstances where the fixes for CVE-2024-32004 are not enough: For example, when obtaining a `.zip` file containing a full copy of a Git repository, it should not be trusted by default to be safe, as e.g. hooks could be configured to run within the context of that repository. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid using Git in repositories that have been obtained via archives from untrusted sources.

CVSS3: 7.3
EPSS: Низкий
msrc логотип

CVE-2024-32465

9 месяцев назад

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2024-32465

около 1 года назад

Git is a revision control system. The Git project recommends to avoid ...

CVSS3: 7.3
EPSS: Низкий
fstec логотип

BDU:2024-04042

около 1 года назад

Уязвимость распределенной системы контроля версий Git, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю обойти защиту при клонировании ненадежных репозиториев

CVSS3: 7.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2277-1

12 месяцев назад

Security update for git

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1854-1

около 1 года назад

Security update for git

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1807-1

около 1 года назад

Security update for git

EPSS: Низкий
rocky логотип

RLSA-2024:4084

12 месяцев назад

Important: git security update

EPSS: Низкий
rocky логотип

RLSA-2024:4083

12 месяцев назад

Important: git security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4084

12 месяцев назад

ELSA-2024-4084: git security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4083

12 месяцев назад

ELSA-2024-4083: git security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0197-1

5 месяцев назад

Security update for git

EPSS: Низкий
redos логотип

ROS-20240527-04

около 1 года назад

Множественные уязвимости git

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-32465

Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but vulnerabilities allow those protections to be bypassed. In the context of cloning local repositories owned by other users, this vulnerability has been covered in CVE-2024-32004. But there are circumstances where the fixes for CVE-2024-32004 are not enough: For example, when obtaining a `.zip` file containing a full copy of a Git repository, it should not be trusted by default to be safe, as e.g. hooks could be configured to run within the context of that repository. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid using Git in repositories that have been obtained via archives from untrusted sources.

CVSS3: 7.3
0%
Низкий
около 1 года назад
redhat логотип
CVE-2024-32465

Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but vulnerabilities allow those protections to be bypassed. In the context of cloning local repositories owned by other users, this vulnerability has been covered in CVE-2024-32004. But there are circumstances where the fixes for CVE-2024-32004 are not enough: For example, when obtaining a `.zip` file containing a full copy of a Git repository, it should not be trusted by default to be safe, as e.g. hooks could be configured to run within the context of that repository. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid using Git in repositories that have been obtained via archives from untrusted sources.

CVSS3: 7.3
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-32465

Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but vulnerabilities allow those protections to be bypassed. In the context of cloning local repositories owned by other users, this vulnerability has been covered in CVE-2024-32004. But there are circumstances where the fixes for CVE-2024-32004 are not enough: For example, when obtaining a `.zip` file containing a full copy of a Git repository, it should not be trusted by default to be safe, as e.g. hooks could be configured to run within the context of that repository. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid using Git in repositories that have been obtained via archives from untrusted sources.

CVSS3: 7.3
0%
Низкий
около 1 года назад
msrc логотип
CVSS3: 7.3
0%
Низкий
9 месяцев назад
debian логотип
CVE-2024-32465

Git is a revision control system. The Git project recommends to avoid ...

CVSS3: 7.3
0%
Низкий
около 1 года назад
fstec логотип
BDU:2024-04042

Уязвимость распределенной системы контроля версий Git, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю обойти защиту при клонировании ненадежных репозиториев

CVSS3: 7.3
0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:2277-1

Security update for git

12 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:1854-1

Security update for git

около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1807-1

Security update for git

около 1 года назад
rocky логотип
RLSA-2024:4084

Important: git security update

12 месяцев назад
rocky логотип
RLSA-2024:4083

Important: git security update

12 месяцев назад
oracle-oval логотип
ELSA-2024-4084

ELSA-2024-4084: git security update (IMPORTANT)

12 месяцев назад
oracle-oval логотип
ELSA-2024-4083

ELSA-2024-4083: git security update (IMPORTANT)

12 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0197-1

Security update for git

5 месяцев назад
redos логотип
ROS-20240527-04

Множественные уязвимости git

CVSS3: 8.1
около 1 года назад

Уязвимостей на страницу